Nu er det som følger:
der står et blåt combofixvindue:
Vent venligst
Adgang nægtet
c:\windows\system32\drivers\combo-fix.sys blev ikke fundet
.
vinduet kan ikke lukkes, bortset fra det ser det ud til at alt er normalt. har ikke sluttet den til nettet endnu
log filen:
ComboFix 09-04-21.01 - HP_Ejer 20-04-2009 21:16.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.45.1030.18.1023.581 [GMT 2:00]
Kører fra: c:\documents and settings\HP_Ejer\Skrivebord\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
* Dannede nyt systemgendannelsespunkt
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HP_Ejer\Application Data\install.dat
c:\documents and settings\HP_Ejer\Application Data\Microsoft\SystemCertificates\Request
c:\documents and settings\HP_Ejer\err.log
c:\documents and settings\Prootools\Application Data\HbTools
c:\documents and settings\Prootools\Application Data\HbTools\HbTools.log
c:\documents and settings\Prootools\Application Data\HbTools\HbTools_1174492327.log
c:\documents and settings\Prootools\Application Data\HbTools_Icons
c:\documents and settings\Prootools\Application Data\HbTools_Icons\games2.ico
c:\documents and settings\Prootools\Application Data\HbTools_Icons\Registryrepair.ico
c:\documents and settings\Prootools\Application Data\HbTools_Icons\wallpapere1.ico
c:\documents and settings\Prootools\Application Data\Install.dat
c:\documents and settings\Prootools\err.log
c:\progra~1\FLLESF~1\{1C507~1
c:\progra~1\FLLESF~1\{3C507~1
c:\progra~1\FLLESF~1\{3C507~1\Bar888.dll
c:\progra~1\FLLESF~1\{3C507~1\UnInstall.exe
c:\programmer\INSTALL.LOG
c:\windows\system32\AutoRun.inf
c:\windows\system32\dfbde1_g.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-03-20 til 2009-04-20 )))))))))))))))))))))))))))))))))))
.
2009-05-03 16:22 . 2009-05-03 16:22 -------- d-----w c:\programmer\plasq
2009-05-03 13:55 . 2009-05-03 13:55 79184 ----a-w c:\windows\system32\BGLsp.dll
2009-05-03 12:58 . 2009-05-03 12:58 63049904 ----a-w C:\avg_free_stf_en_85_285a1462.exe
2009-04-20 16:03 . 2009-04-20 16:03 -------- d-----w c:\documents and settings\HP_Ejer\Application Data\Malwarebytes
2009-04-20 16:03 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-20 16:03 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-20 16:03 . 2009-04-20 16:03 -------- d-----w c:\programmer\Malwarebytes' Anti-Malware
2009-04-20 16:03 . 2009-04-20 16:03 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-19 10:22 . 2009-04-19 10:37 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-04-19 10:22 . 2009-04-19 10:37 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-04-19 10:21 . 2009-04-20 19:22 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-19 10:21 . 2009-04-20 19:22 573472 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-19 10:21 . 2009-04-20 19:22 3040 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-19 10:21 . 2009-04-20 19:20 4150304 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-19 10:21 . 2009-04-20 19:20 33504 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-19 10:21 . 2009-04-19 10:21 -------- d-----w c:\programmer\Kaspersky Lab
2009-04-19 09:48 . 2009-04-19 09:48 23 ----a-w c:\windows\system32\afddbeab_g.ocx
2009-04-19 09:47 . 2009-04-19 09:48 -------- d-----w c:\programmer\RegSupreme
2009-04-19 09:32 . 2009-04-19 09:32 -------- d-----w c:\programmer\CCleaner
2009-04-18 14:34 . 2009-04-18 14:34 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-04-18 13:48 . 2009-04-18 13:48 406 ----a-w c:\windows\system32\ioloBootDefrag.cfg
2009-04-18 13:48 . 2009-04-18 13:48 -------- d-----w c:\documents and settings\HP_Ejer\Application Data\iolo
2009-04-18 13:48 . 2009-04-18 13:48 -------- d-----w c:\documents and settings\All Users\Application Data\iolo
2009-04-15 21:22 . 2009-04-15 21:22 -------- d-----w c:\programmer\MSSOAP
2009-04-15 18:31 . 2009-04-15 21:22 164 ----a-w c:\windows\install.dat
2009-04-14 18:58 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-14 18:58 . 2009-03-06 14:20 284672 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-14 18:58 . 2009-02-09 11:25 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-14 18:58 . 2009-02-09 10:53 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-14 18:58 . 2009-02-09 10:53 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-14 18:58 . 2009-02-09 10:53 682496 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-14 18:58 . 2009-02-09 10:53 730624 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-14 18:58 . 2009-02-09 10:53 719360 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-14 18:58 . 2009-02-09 10:53 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-14 18:58 . 2009-03-27 06:53 1203922 -c----w c:\windows\system32\dllcache\sysmain.sdb
2009-04-14 18:58 . 2008-04-21 21:15 217088 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-01 12:09 . 2009-04-01 12:09 -------- d-----w c:\documents and settings\LocalService\Lokale indstillinger\Application Data\HP
2009-04-01 08:02 . 2009-04-01 08:02 -------- d-----w C:\temp
2009-03-25 12:14 . 2009-03-25 12:14 4 --shatr c:\documents and settings\All Users\Application Data\sysqcl1129139270.dat
2009-03-25 12:12 . 2009-03-25 12:12 11770368 ----a-w C:\comiclife-win.exe
2009-03-23 14:43 . 2009-04-20 19:22 -------- d-----w c:\documents and settings\HP_Ejer\Tracing
2009-03-23 14:41 . 2009-03-23 14:41 -------- d-----w c:\programmer\Microsoft
2009-03-23 14:41 . 2009-03-23 14:41 -------- d-----w c:\programmer\Windows Live SkyDrive
2009-03-23 14:39 . 2009-03-23 14:39 -------- d-----w c:\programmer\Fælles filer\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-03 15:45 . 2007-05-14 15:51 -------- d-----w c:\programmer\Fælles filer\Wise Installation Wizard
2009-04-19 10:37 . 2008-01-29 15:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-04-19 09:57 . 2008-01-07 17:13 4212 ---ha-w c:\windows\system32\zllictbl.dat
2009-04-19 09:56 . 2009-03-18 23:41 -------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-04-15 21:25 . 2008-12-18 13:36 -------- d-----w c:\documents and settings\All Users\Application Data\Webroot
2009-04-15 21:19 . 2008-12-25 16:50 39378704 ----a-w C:\SpySweeperRegSetup_GBR.exe
2009-04-15 21:13 . 2006-02-28 20:19 -------- d-----w c:\programmer\Google
2009-04-15 13:25 . 2004-01-01 15:22 64750 ----a-w c:\windows\system32\perfc006.dat
2009-04-15 13:25 . 2004-01-01 15:22 400142 ----a-w c:\windows\system32\perfh006.dat
2009-04-06 11:32 . 2008-12-25 16:56 1563008 ----a-w c:\windows\WRSetup.dll
2009-04-02 12:30 . 2008-12-18 13:36 176752 ----a-w c:\windows\system32\drivers\ssidrv.sys
2009-04-02 12:30 . 2008-12-18 13:36 23152 ----a-w c:\windows\system32\drivers\sshrmd.sys
2009-04-02 12:30 . 2008-08-09 13:42 29808 ----a-w c:\windows\system32\drivers\ssfs0bbc.sys
2009-04-01 07:47 . 2008-12-18 11:53 4931413 ----a-w c:\windows\Internet Logs\tvDebug.Zip
2009-03-26 17:37 . 2008-07-10 17:12 267152 ----a-w C:\zaSetup_en.exe
2009-03-23 14:43 . 2005-02-20 12:47 89696 ----a-w c:\documents and settings\HP_Ejer\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2009-03-23 14:41 . 2008-01-27 13:01 -------- d-----w c:\programmer\Windows Live
2009-03-16 09:13 . 2009-03-16 09:13 268 ---ha-w C:\sqmdata12.sqm
2009-03-16 09:13 . 2009-03-16 09:13 244 ---ha-w C:\sqmnoopt12.sqm
2009-03-06 14:20 . 2004-01-01 14:25 284672 ----a-w c:\windows\system32\pdh.dll
2009-03-06 14:10 . 2007-01-23 17:19 -------- d-----w c:\programmer\Yahoo!
2009-03-05 14:59 . 2009-03-02 13:00 -------- d-----w c:\documents and settings\HP_Ejer\Application Data\U3
2009-03-03 00:11 . 2006-06-23 11:27 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-26 09:51 . 2008-06-22 18:54 -------- d-----w c:\programmer\Microsoft Silverlight
2009-02-23 21:37 . 2009-02-23 21:37 -------- d-----w c:\programmer\MSECache
2009-02-20 17:12 . 2007-06-27 13:04 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-10 17:08 . 2002-09-09 21:07 2068608 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 14:07 . 2004-01-01 15:22 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:26 . 2004-01-01 15:22 2191616 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:25 . 2004-01-01 14:26 110592 ----a-w c:\windows\system32\services.exe
2009-02-09 10:53 . 2004-01-01 15:22 730624 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:53 . 2005-07-26 04:38 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:53 . 2004-01-01 15:22 719360 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 10:53 . 2004-01-01 14:19 682496 ----a-w c:\windows\system32\advapi32.dll
2009-02-06 17:52 . 2009-02-06 17:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-06 10:39 . 2004-01-01 14:26 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:58 . 2004-01-01 14:26 56832 ----a-w c:\windows\system32\secur32.dll
2006-04-20 14:54 . 2006-04-20 14:54 70104 ----a-w c:\documents and settings\Prootools\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2005-02-21 16:29 . 2005-02-21 16:29 0 ---ha-w c:\programmer\Fælles filer\MSN
2005-02-20 12:47 . 2007-04-01 13:07 136 ----a-w c:\documents and settings\HP_Ejer\Lokale indstillinger\Application Data\fusioncache.dat
2004-01-01 09:43 . 2006-04-20 14:54 133 ----a-w c:\documents and settings\Prootools\Lokale indstillinger\Application Data\fusioncache.dat
1998-02-10 15:34 . 2006-04-20 16:02 128000 ----a-w c:\programmer\UNWISE.EXE
2007-06-15 10:09 . 2007-06-15 10:09 53 --sha-w c:\windows\system32\475037660.dat
2008-10-21 14:21 . 2008-10-21 14:22 32768 --sha-w c:\windows\system32\config\systemprofile\Lokale indstillinger\Oversigt\History.IE5\MSHist012008102120081022\index.dat
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-19 68856]
"MsnMsgr"="c:\programmer\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"updateMgr"="c:\programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\programmer\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"Home Theater SchSvr"="c:\programmer\Fælles filer\InterVideo\SchSvr\SchSvr.exe" [2004-08-20 155648]
"WINREMOTE"="c:\programmer\InterVideo\Common\Bin\WinRemote.exe" [2004-06-25 192512]
"iTunesHelper"="c:\programmer\iTunes\iTunesHelper.exe" [2004-05-11 286720]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2004-07-12 4112384]
"nwiz"="c:\windows\system32\nwiz.exe" [2004-07-12 843776]
"SiS Windows KeyHook"="c:\windows\System32\keyhook.exe" [2004-05-20 249856]
"AlcxMonitor"="c:\windows\ALCXMNTR.EXE" [2003-04-04 50176]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2003-12-17 118784]
"SetDefaultPrinter"="c:\hp\bin\cloaker.exe" [1999-11-07 27136]
"Sony Ericsson PC Suite"="c:\programmer\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" [2009-01-05 413696]
"AVP"="c:\programmer\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-04-19 206088]
"SpySweeper"="c:\programmer\Webroot\Spy Sweeper\SpySweeperUI.exe" [2009-04-06 6345840]
c:\documents and settings\HP_Ejer\Menuen Start\Programmer\Start\
Yahoo! Widgets.lnk - c:\programmer\Yahoo!\Widgets\YahooWidgets.exe [2008-3-19 4742184]
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
Adobe Gamma Loader.lnk - c:\programmer\F‘lles filer\Adobe\Calibration\Adobe Gamma Loader.exe [2006-3-14 113664]
Adobe Reader Hurtigstart.lnk - c:\programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
R3 SE31bus;Sony Ericsson Device 049 Driver driver (WDM);c:\windows\system32\DRIVERS\SE31bus.sys [2006-05-01 61600]
R3 SE31mdfl;Sony Ericsson Device 049 USB WMC Modem Filter;c:\windows\system32\DRIVERS\SE31mdfl.sys [2006-05-01 9360]
R3 SE31mdm;Sony Ericsson Device 049 USB WMC Modem Driver;c:\windows\system32\DRIVERS\SE31mdm.sys [2006-05-01 97184]
R3 SE31mgmt;Sony Ericsson Device 049 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\SE31mgmt.sys [2006-05-01 88688]
R3 SE31obex;Sony Ericsson Device 049 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\SE31obex.sys [2006-05-01 86560]
R3 V0260VID;Live! Cam Vista IM;c:\windows\system32\DRIVERS\V0260Vid.sys [2006-04-01 162176]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-04-19 33808]
S0 ssfs0bbc;ssfs0bbc;c:\windows\system32\DRIVERS\ssfs0bbc.sys [2009-04-02 29808]
S2 WRConsumerService;Webroot Client Service;c:\programmer\Webroot\Spy Sweeper\WRConsumerService.exe [2009-04-15 1181040]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
S3 PhTVTune;ASUS WDM TV Tuner;c:\windows\system32\DRIVERS\PhTVTune.sys [2004-05-27 24608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9f3c690-0729-11de-ae0c-0011d827ff81}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
.
Indhold af mappen 'Planlagte Opgaver'
2009-03-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmer\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-05-04 c:\windows\Tasks\wrSpySweeperFullSweep.job
- c:\programmer\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-12-18 11:32]
2009-05-04 c:\windows\Tasks\wrSpySweeperFullSweep.job
- c:\programmer\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-12-18 11:32]
2009-04-16 c:\windows\Tasks\wrSpySweeper_L1B08CB7E35E74326A2D227E5053F8841.job
- c:\programmer\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-12-18 11:32]
2009-04-16 c:\windows\Tasks\wrSpySweeper_L1B08CB7E35E74326A2D227E5053F8841.job
- c:\programmer\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-12-18 11:32]
.
- - - - TOMME GENVEJE FJERNET - - - -
HKLM-Run-VTTimer - VTTimer.exe
Notify-avgrsstarter - avgrsstx.dll
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/webhp?rls=iguSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\bglsp.dll
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\programmer\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: {07E8D22D-C723-485C-BE6F-003241549305} -
hxxp://extcom.esoft.dk/extern/3d/eplan.cab.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-20 21:23
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'lsass.exe'(916)
c:\windows\system32\bglsp.dll
- - - - - - - > 'explorer.exe'(2128)
c:\windows\system32\nview.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\nvwddi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\programmer\Webroot\Spy Sweeper\SpySweeper.exe
c:\programmer\iPod\bin\iPodService.exe
c:\windows\system32\rundll32.exe
c:\programmer\Fælles filer\Teleca Shared\CapabilityManager.exe
c:\programmer\HP\Digital Imaging\bin\hpqtra08.exe
c:\programmer\HP\Digital Imaging\bin\hpqste08.exe
c:\windows\system32\wscntfy.exe
c:\programmer\Webroot\Spy Sweeper\SSU.exe
.
**************************************************************************
.
Gennemført tid: 2009-04-20 22:15 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2009-04-20 20:15
Pre-Kørsel: 131.137.323.008 byte ledig
Post-Kørsel: 131.999.539.200 byte ledig
248 --- E O F --- 2009-04-14 21:00